MEDIUM · 4.7

CVE-2022-20728

A vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an unauthenticated, adjacent attacker to inject packets from the native VLAN to clients within nonnative...

Vulnerability Description

A vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an unauthenticated, adjacent attacker to inject packets from the native VLAN to clients within nonnative VLANs on an affected device. This vulnerability is due to a logic error on the AP that forwards packets that are destined to a wireless client if they are received on the native VLAN. An attacker could exploit this vulnerability by obtaining access to the native VLAN and directing traffic directly to the client through their MAC/IP combination. A successful exploit could allow the attacker to bypass VLAN separation and potentially also bypass any Layer 3 protection mechanisms that are deployed.

CVSS Score

4.7

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
NONE
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
CiscoAironet 1542D Firmware017.006\(001\)
CiscoAironet 1542D-
CiscoAironet 1542I Firmware017.006\(001\)
CiscoAironet 1542I-
CiscoAironet 1562I Firmware017.006\(001\)
CiscoAironet 1562I-
CiscoAironet 1562E Firmware017.006\(001\)
CiscoAironet 1562E-
CiscoAironet 1562D Firmware017.006\(001\)
CiscoAironet 1562D-
CiscoAironet 1815I Firmware017.006\(001\)
CiscoAironet 1815I-
CiscoAironet 1815M Firmware017.006\(001\)
CiscoAironet 1815M-
CiscoAironet 1815T Firmware017.006\(001\)
CiscoAironet 1815T-
CiscoAironet 1815W Firmware017.006\(001\)
CiscoAironet 1815W-
CiscoAironet 1830 Firmware017.006\(001\)
CiscoAironet 1830-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-20728?

CVE-2022-20728 is a vulnerability with a CVSS score of 4.7 (MEDIUM). A vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an unauthenticated, adjacent attacker to inject packets from the native VLAN to clients within nonnative...

How severe is CVE-2022-20728?

CVE-2022-20728 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-20728?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Aironet 1542D Firmware, Cisco Aironet 1542D, Cisco Aironet 1542I Firmware, Cisco Aironet 1542I, Cisco Aironet 1562I Firmware.